← Back to browse · API

CVE-2018-5430

Severity
HIGH
CVSS
7.7
EPSS
0.48753
Risk score
72.86
CISA KEV
Yes
PoC
No
Published
2018-04-17
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2018-17200, GHSA-782F-H7V4-M7WC
Products
TIBCO Software Inc.:TIBCO JasperReports Server 6.3.0, TIBCO Software Inc.:TIBCO JasperReports Server 6.3.2, TIBCO Software Inc.:TIBCO JasperReports Server 6.3.3, TIBCO Software Inc.:TIBCO JasperReports Server 6.4.0, TIBCO Software Inc.:TIBCO JasperReports Server 6.4.2, TIBCO Software Inc.:TIBCO JasperReports Server Community Edition unspecified ≤6.4.2, TIBCO Software Inc.:TIBCO JasperReports Server for ActiveMatrix BPM unspecified ≤6.4.2, TIBCO Software Inc.:TIBCO JasperReports Server unspecified ≤6.2.4, TIBCO Software Inc.:TIBCO Jaspersoft Reporting and Analytics for AWS unspecified ≤6.4.2, TIBCO Software Inc.:TIBCO Jaspersoft for AWS with Multi-Tenancy unspecified ≤6.4.2, TIBCO:JasperReports
Sources
cisa.gov CVE-2018-5430
euvd EUVD-2018-17200

Description

The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.

References